Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4842 Views
  • 0 replies
  • 0 Likes

Resolved! SDWAN PAN-OS and Panorama - Docs are rough

I am working through the panorama/sdwan plugin docs for a new deployment using Nextgen firewalls' built in SDWAN, all on 10.0.6 and the plugin version is 2.1In the docs there seems to be some conflicting advice. See below. Anyone know which is correct here? I have to ship these devices off, and obviously having this setting wrong will cause some...

dpayne_0-1623254186161.png
dpayne by L1 Bithead
  • 3533 Views
  • 2 replies
  • 0 Likes

Resolved! eventid: mem-limit-exceeded in Panorama

We have received below email alert from Panorama , what is the meaning of this high severity system logs ?actionflags: 0x0type: SYSTEMsubtype: resctrlconfig_ver: 0time_generated: 2021/06/04 08:41:01high_res_timestamp: 2021-06-04T08:41:01.000+05:30dg_hier_level_1: 0dg_hier_level_2: 0dg_hier_level_3: 0dg_hier_level_4: 0vsys_name:device_name: Panor...

Deepak25 by L3 Networker
  • 3797 Views
  • 1 replies
  • 0 Likes

master device in panorama device-group if using dataplane interface

Due to high cpu utilization in firewall , we want to use dataplane interface of firewall for user-id services.Currently , when primary firewall failover to secondary we do not require to change master device in panorama device-group.How panorama collecting user-id info if primary firewall which selected as a master in device-group becomes passiv...

Deepak_K_0-1622112578545.png
Deepak_K by L3 Networker
  • 3942 Views
  • 3 replies
  • 0 Likes

Resolved! Do we need to separately upgrade a local log collector during a Panorama upgrade?

Hi All, We are going to perform a Panorama upgrade from 8.1.15 to 9.1.9. The upgrade path is 8.1.15 --> 8.1.19 --> 9.0 (Download Only) --> 9.0.13 --> 9.1 ( Download Only ) --> 9.1.9 ( Preferred version ). In this environment, there is a local log collector configured in the same Panorama ( Collector serial number is the same as th...

Udana by L1 Bithead
  • 3776 Views
  • 3 replies
  • 0 Likes

Panorama mgmt CPU usage

We are managing 4 location HA pair from Panorama and collecting logs using management interface of M200. (all devices and panorama in same data centre)Sometimes we observed delay in logs and commit operation , but mgmt cpu of M200 is less than 50% at that time.mgmt cpu utilization in panorama is showing utilization of only mgmt interface or over...

Deepak_K by L3 Networker
  • 4258 Views
  • 1 replies
  • 0 Likes

Pamorama Management Only Mode not show log on GUI

We have issue about Panorama Management Only Mode not show logs.We have M-200 run on Collector mode and Panorama-VM run on Management Only.This's new setup and the firewall can forward log to collector but Panorama Management Only mode not show log on GUI. We tried to restart and reboot the panorama. > debug software restart log-receiver , &g...

Jitaphon by L2 Linker
  • 3048 Views
  • 2 replies
  • 0 Likes

Resolved! Panorama compatibility with previous versions

Do you know if Panorama could manage firewalls with versions far from the actual? For example, if I have a Panorama running version 10.0.x, can I manage firewalls running 8.0.x, 8.1.x, 9.0.x? or how many previous version could manage?

emendezo by L1 Bithead
  • 4377 Views
  • 2 replies
  • 0 Likes

Panorama GUI wont respond after upgrading beyond 10.0.0

We upgraded to 10.0.0 and all was well until we realised we cant upload variables in to our templates. Then found the bug fix was resolved in 10.0.1 and above. Now that we try to upgrade to any version beyond 10.0.0 up to the latest 10.0.6 SSH remains functional however the web gui crashes. I've already reset the management web services which ha...

Is the Palo Alto Device name that is configured under "Panorama > SD-WAN > Devices" the hostname of the firewall?

My question is the Device name under "Panorama > SD-WAN > Devices" the hostname of the firewall under "Device > Setup > Management"? Is this the way the firewall knows for example that it is "branch-1" in the SD-WAN cluster configuration? https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/panorama-web-interface/...

Panorama system logs -> Sending to Slack via HTTP profile -> NEED TO SEND PANORAMA DEVICE HOSTNAME

I am using an HTTP profile to send PANORAMA CRITICAL SYSTEM events to Slack. The integration is working well. My Panoramas are an A/P HA cluster. The issue that I have is that I'm unable to delineate the device names via the HTTP profile payload (because the HTTP profile payload gets duplicated between both the active and the passive device). ...

Panorama Managed Device Health Report Using Email schedule

Hi All, I am trying to see if we can automate functionality to generate device health reports daily using Panorama. I have checked the custom report but don't see any option. Currently, I am pulling details manually using -- Panorama ----- > managed device --- > health. Any help in this regard would be great.

Sambhu21 by L1 Bithead
  • 2983 Views
  • 1 replies
  • 1 Likes

Panorama takes excessive time to complete commit to firewalls, stuck at 50%

The push to the standby firewall occurs quickly (1-3 minutes).The push to the active firewall is stuck for a long time. I notice the config does finally get to the active firewall, but Panorama still shows push in progress.Note in the second picture that the push completed to the standby firewall already, but stuck at the active firewall.

Panorama push stuck at 50-1.JPG
Panorama push stuck at 50-2.JPG
bkoch709 by L1 Bithead
  • 7268 Views
  • 4 replies
  • 0 Likes

Resolved! Panorama M-200 HA config sync failure

I am working on configuring HA for new Panorama M-200 devices. Since we replacing existing M-200 devices, the HA settings are migrated from working M-100 pair. The HA connectivity seems to be fine since I both Panorama can see each others status and shows state in the dashboard. The problem is that one of the Panorama showing App Version and Ant...

Sly_Cooper_1-1620240139103.png
Sly_Cooper_0-1620240088295.png
Sly_Cooper_2-1620240204496.png

Panorama HA upgrade to 10.0

We have query regarding log collector group while upgrading Panorama M200 Ha pair from PANOS 9.1.6 to PANOS 10.0.5.Is there any issue in log collector status or log forwarding to collector group ?We have log collector group( with enable log redundancy) and local log collector of both panorama are added into same LC group in our production set...

Deepak_K_1-1620044981817.png
Deepak_K_2-1620045346093.png
Deepak_K by L3 Networker
  • 5048 Views
  • 4 replies
  • 0 Likes
  • 845 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors